Live data from Hacker News

Tailscale didn't stop the Hugging Face intrusion

tailscale.com

11–20 of 239 posts

Re: Tailscale didn't stop the Hugging Face intrusion

#11
>In the old world where most intrusions were done by humans at human speed, credential leak mitigations were treated as a nice-to-have. A big credential store, where you can read 136 keys at once, was a to-do item somewhere in a security team's low-priority list. >Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore.

How was this ever okay pre AI? It seems just as bad.

Re: Tailscale didn't stop the Hugging Face intrusion

#12

I'm very sorry, but you can't blame a hammer for how it was used. You can't be blaming Tailscale for a customer's misconfigured setup.

You know how I know you didn't read the article?

You can't blame a hammer hurting a user when they were being stupid, but if the default configuration of the hammer is to be made of a material that can bounce back with force and stick in the users forehead then some reengineering may be needed.

That's what this article is about. Better configurations and defense in depth. This is actually a wonderful position for the company to think about and take.

Re: Tailscale didn't stop the Hugging Face intrusion

#13
post #10
post #5

Earlier quoted context omitted.

This has been discussed heavily for the better part of 15 years now, and still no one has consensus on what to do about it. So it looks like it's just going to happen, fingers crossed.

The watcher looks down upon humanity as they furiously build the "If anybody builds it, everyone will die" machine.

And humanity acts surprised with the results!

Re: Tailscale didn't stop the Hugging Face intrusion

#16

[flagged]

Something about your comment comes across as AI to me. I can't really place my finger on it. It's too subtle for that. It's more the vibe of your entire comment that makes me feel it.

Please, when commenting on HN, don't use AI to write your comments. You can afford to help keep this a human-centric place.

Re: Tailscale didn't stop the Hugging Face intrusion

#17

>In the old world where most intrusions were done by humans at human speed, credential leak mitigations were treated as a nice-to-have. A big credential store, where you can read 136 keys at once, was a to-do item somewhere in a security team's low-priority list. >Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore. How was this ever okay pre AI? It seems just as bad.

It was less bad due to the lower speed of exploatation. Imagine you leave a dor open for few seconds and ultra fast AI bot comes on and steal your stuff. Something that was not such an issue before becomes huge issue just due to speed involved

Re: Tailscale didn't stop the Hugging Face intrusion

#19
post #12

I'm very sorry, but you can't blame a hammer for how it was used. You can't be blaming Tailscale for a customer's misconfigured setup.

You know how I know you didn't read the article? You can't blame a hammer hurting a user when they were being stupid, but if the default configuration of the hammer is to be made of a material that can bounce back with force and stick in the users forehead then some reengineering may be needed. That's what this article is about. Better configurations and defense in depth. This is actually a wonderful position for the…

It's an interesting balance for a company to strike. Networking in general is one where the defaults are almost always lax. Why? Because the vast majority of support tickets for these companies are from people who don't know what they are doing and don't have a desire to understand. They "just want it to work."

But the people with the actual desire and understanding aren't using the defaults anyway. And the people who don't want to understand will just turn things off and "just get it working."

The only way out of this is extreme accountability and intentional design from person implementing the technology.

Re: Tailscale didn't stop the Hugging Face intrusion

#20

> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

Glad to see companies owning responsibility and putting out a message without corporate PR spin
Post reply on HN